Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Cordova
(Apache)Repositories |
• https://github.com/apache/cordova-plugin-file-transfer
• https://github.com/apache/cordova-plugin-inappbrowser |
#Vulnerabilities | 18 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-10-27 | CVE-2015-1835 | Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL. | Cordova | 5.3 | ||
2014-11-15 | CVE-2014-3502 | Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent. | Cordova | N/A | ||
2014-11-15 | CVE-2014-3501 | Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView. | Cordova | N/A | ||
2014-11-15 | CVE-2014-3500 | Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL. | Cordova | N/A | ||
2014-03-03 | CVE-2014-1884 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application. | Phonegap, Cordova | N/A | ||
2014-03-03 | CVE-2014-1882 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses bridge JavaScript objects, as demonstrated by certain cordova.require calls. | Phonegap, Cordova | N/A | ||
2014-03-03 | CVE-2014-1881 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain amount of time for an OnJsPrompt handler return value as an alternative to correct synchronization. | Phonegap, Cordova | N/A | ||
2014-03-03 | CVE-2012-6637 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring. | Phonegap, Cordova | N/A |